# How to get the Top Hit result from the aggregated 95th percentile

**URL:** <https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117>\
**Category:** Elasticsearch\
**Created:** [December 17, 2018, 10:26am UTC](https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117 "2018-12-17T10:26:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![\_kyllr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_kyllr/32/27610_2.png) [@\_kyllr](https://discuss.elastic.co/u/_kyllr)\
**Post date:** [December 17, 2018, 10:26am UTC](https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117/1 "2018-12-17T10:26:55Z")

</div>

Hello,

I have this visualization below to get the 95th percentile per hour:

```
{
  "size": 0,
  "_source": {
"excludes": []
  },
  "aggs": {
"2": {
  "date_histogram": {
    "field": "AuthorizationUTCTimestamp",
    "interval": "1h",
    "time_zone": "Asia/Shanghai",
    "min_doc_count": 1
  },
  "aggs": {
    "1": {
      "percentiles": {
        "field": "TokenRequest",
        "percents": [
          95
        ],
        "keyed": false
      }
    }
  }
}
  },
  "stored_fields": [
"*"
  ],
  "script_fields": {},
  "docvalue_fields": [
"AuthorizationUTCTimestamp",
"IssuedUTCTimestamp",
"signinDateTime"
  ],
  "query": {
"bool": {
  "must": [
    {
      "match_all": {}
    },
    {
      "range": {
        "AuthorizationUTCTimestamp": {
          "gte": 1544284800000,
          "lte": 1544371199999,
          "format": "epoch_millis"
        }
      }
    }
  ],
  "filter": [],
  "should": [],
  "must_not": []
}
  }
}

```

Now, what I would like to achieve is to get the max result of 95th percentile per day based in the result from above request.

Is there anyway I can get the top hit from the aggregations result?

Thanks!

---

<div class="post-metadata">

**Author:** ![monfera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/monfera/32/26467_2.png) [@monfera](https://discuss.elastic.co/u/monfera)\
**Post date:** [December 17, 2018, 10:54am UTC](https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117/2 "2018-12-17T10:54:15Z")

</div>

Hi @_kyllr it may be more of an Elasticsearch question - if these links don't offer a solution, please tag the question as ES.

[Pipeline aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html#search-aggregations-pipeline)  
[Sub-aggregations](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-bucket-composite-aggregation.html#_sub_aggregations)

---

<div class="post-metadata">

**Author:** ![\_kyllr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_kyllr/32/27610_2.png) [@\_kyllr](https://discuss.elastic.co/u/_kyllr)\
**Post date:** [December 17, 2018, 11:08am UTC](https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117/3 "2018-12-17T11:08:21Z")

</div>

Hi @monfera, already tagged this as ES. Thanks!

---

<div class="post-metadata">

**Author:** ![\_kyllr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/_kyllr/32/27610_2.png) [@\_kyllr](https://discuss.elastic.co/u/_kyllr)\
**Post date:** [December 18, 2018, 9:37am UTC](https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117/4 "2018-12-18T09:37:11Z")

</div>

Hello, could someone help on this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 15, 2019, 9:50am UTC](https://discuss.elastic.co/t/how-to-get-the-top-hit-result-from-the-aggregated-95th-percentile/161117/5 "2019-01-15T09:50:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
